Frameworks

One Control Library. Multiple Frameworks.

Every control lives once, in one library. The V17-E Framework Crosswalk Engine maps it onto the specific requirements of every framework you're scoped to — so adding a framework recomputes applicability against controls you already have. You are never re-assessed from zero.

The parent concept

ONE CONTROL LIBRARY.

Frameworks below aren't separate products or separate assessments — they're views onto the same control library, deterministically crosswalked. One control library. Multiple frameworks. Less duplicate work.

NIST

NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, Recover — the six functions, subcategory by subcategory.

NIST SP 800-171 (Rev 2 / Rev 3)

Controlled Unclassified Information (CUI) protection requirements for federal contractors and subcontractors.

CMMC (Level 1 / Level 2)

DoD's Cybersecurity Maturity Model Certification baseline, built on the same 800-171 control set.

CIS Controls v8.1

Prioritized safeguards used as a practical implementation baseline across the control library.

ISO

ISO/IEC 27001

Information security management system controls and the Statement of Applicability.

ISO/IEC 42001

AI management system requirements — governance for the AI systems your business builds or uses.

Compliance

SOC 2

Trust Services Criteria — security, availability, confidentiality, and the rest, mapped control-by-control.

HIPAA

Administrative, physical, and technical safeguards for protected health information.

PCI DSS

Payment card data protection requirements, scoped to your SAQ or ROC.

Financial Services

GLBA Safeguards Rule

FTC's written information security program requirement, 16 CFR Part 314.

FFIEC

The FFIEC IT Examination Handbook's information security and business continuity expectations for banks.

NCUA

Part 748 and ACET expectations for credit unions.

See all 26 free scored assessments

Not sure which frameworks apply to you?

30 minutes. No obligation. No sales pitch.

Talk to a CISO